Know your vendors. Protect your data.
Factual vendor compliance data: certifications, subprocessors, DPAs, litigation history and AI governance. Structured once, accessible to everyone.
No credit card required ยท Free forever for vendors
24
18
21
14
| Vendor | Category | Score | Certifications | Status |
|---|---|---|---|---|
| Stripe | Payments | 9/9 | SOC 2ISO 27001 | Verified |
| Slack | Communication | 7/9 | SOC 2 | Verified |
| Notion | Productivity | 6/9 | SOC 2ISO 27001 | Pending |
| Hubspot | Marketing | 5/9 | SOC 2 | Pending |
Trusted by Fortune 500 CPOs. Leveraged by successful SaaS.
What you get
Everything you need to evaluate vendors
Transparency Scores
9-point factual scoring: certs, DPA, trust center, subprocessors, privacy policy, verified claims.
Subprocessor Chains
See who your vendors share data with down the chain. Oregon SB 619 & EDPB require it. We make it visible.
Privacy Litigation
Real US federal court cases from Seneca: BIPA, CCPA, ECPA lawsuits tied to each vendor.
AI Governance
EU AI Act roles, model inventories, bias monitoring and risk tiers. Know if a vendor is an AI system.
Vendor-Verified Data
Vendors claim their profile, complete a questionnaire once, and serve all future customers.
DPA Processing
We locate, catalog, and analyze every vendor's Data Processing Agreement for GDPR, CCPA, and US state law compliance.
Change Detection
Vendors revise DPAs and subprocessor lists without telling anyone. We re-check their published documents monthly and flag what changed, before it surprises your audit.
Subprocessor visibility
Follow the data chain
Oregon SB 619 & the EDPB require identifying all subprocessors down the chain. We give you full visibility, from your vendor to their sub-sub-processors.
Vendor profiles
Deep compliance data for every vendor
Certifications, subprocessors, litigation risk, AI governance indicators and transparency scores. All in one structured profile.
- Transparency score from 9 factual data points
- DPA compliance analysis across GDPR, CCPA & US state laws
- Subprocessor list with processing roles
- Privacy litigation data from US federal courts
- AI governance: EU AI Act roles & model inventory
- One-click executive report: certification coverage, DPA scores, data residency, AI inventory, and gaps across your portfolio
- Fourth-party concentration: see which providers sit beneath most of your vendors
- Filter the catalog by certification, EU data center, DPA availability, and verification status
Datadog
See inside any stack, any app, at any scale, anywhere.
DPA Compliance
Certifications
Subprocessors
Data Locations
Compliance
Ecosystem
How it all connects
Build once, sync everywhere. Export batches of 10 vendors to DPO Central or AI Sentinel. Litigation data flows in automatically from Seneca.
Vendor.Watch
Vendor data transparency hub
DPO Central
Privacy compliance management
Seneca
Privacy litigation data from US federal courts
AI Sentinel
AI risk governance
How it works
From search to export in four steps
Browse & Add
Search 884+ enriched vendors. Add to your portfolio.
5 Free Reviews
Incomplete profiles enriched by our team within 48 hours. First 5 free.
Tag & Classify
Data categories, processing purposes, criticality level.
Export
Push batches of 10 to DPO Central or AI Sentinel.
For vendors
Claim once. Serve every customer.
Show your AI governance on your terms. Declare the models behind your AI features, with provider, EU AI Act risk tier, and model cards, and your profile earns Transparent AI status. If your published subprocessor list names an AI provider but no models are declared, profiles show AI use as undisclosed. Transparency is self-serve, and it is free.
Claim your profile
Domain verification in seconds via Google OAuth or work email.
Complete your questionnaire
Certs, subprocessors, data locations and AI governance, structured once.
Build trust at scale
Verified badge, transparency score, visible to every business on the platform.
Expert verification
Beyond automation
Expert verification when it matters.
Compliance Expert in the Loop
Certified privacy professionals review vendor compliance posture. Independent verification.
Privacy Engineer in the Loop
Technical specialists verify security controls, encryption, and data architecture claims.
Public Attestation
Verified vendors get a public compliance attestation on Comply.org, an open standard anyone can audit.